Runtime for the boxes.dev CLI. Install @boxes-dev/dvb to use the CLI.
No install-time or import-time attack was established from the readable manifest and CLI launcher. The required notices archive is compressed binary and could not be text-cited, so a source-grounded clean decision cannot be finalized.
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgThis report applies to @boxes-dev/dvb-runtime@1.0.1036.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkg